This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I need help [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 20-08-2017
Uruchomiony przez Grzegorz (administrator)  GRZEGORZ-POTFUR (07-09-2017 17:40:19)
Uruchomiony z E:\
Załadowane profile: Grzegorz (Dostępne profile: Grzegorz)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Język: Polski (Polska)
Internet Explorer Wersja 11 (Domyślna przeglądarka: FF)
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(© 2015 Microsoft Corporation) C:\Users\Grzegorz\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Spotify Ltd) C:\Users\Grzegorz\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
(MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
() C:\Windows\System32\PnkBstrA.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe

==================== Rejestr (filtrowane) ====================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM\…\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [239856 2017-09-06] (AVAST Software)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Run: [aemskykoor] => explorer "hxxp://emargan.ru/?utm_source=uoua03&utm;_content=dd5854e571ad34099da3550de30a623c&utm;_term=60D4449A61B3A2E9E44C3C334500D7F0&utm;_d=20170328" <==== UWAGA
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Run: [BingSvc] => C:\Users\Grzegorz\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8912088 2016-08-26] (Piriform Ltd)
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Run: [Spotify Web Helper] => C:\Users\Grzegorz\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1580144 2017-08-30] (Spotify Ltd)
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\MountPoints2: {987be257-8ee5-11e7-b99c-d8cb8abed7e3} - E:\startme.exe
Startup: C:\Users\Grzegorz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 1510 series.lnk [2017-09-07]
ShortcutTarget: Powiadomienia monitorowania tuszu - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
GroupPolicy: Ograniczenia <==== UWAGA
GroupPolicy\User: Ograniczenia <==== UWAGA
GroupPolicyScripts: Ograniczenia <==== UWAGA
GroupPolicyScripts\User: Ograniczenia <==== UWAGA

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1
Tcpip\..\Interfaces\{76AAFD53-1261-4329-80CC-BD1BB16F733D}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{CB165650-2071-4732-A222-D2D16F166507}: [DhcpNameServer] 192.168.8.1

Internet Explorer:
==================
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={SearchTerms}&product;_id=%7B624A8B4D-8F3A-43D8-9999-940F8893C47F%7D&gp;=811014
SearchScopes: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={SearchTerms}&product;_id=%7B624A8B4D-8F3A-43D8-9999-940F8893C47F%7D&gp;=811014
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-09-06] (AVAST Software)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-18] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-09-06] (AVAST Software)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-18] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000 -> Brak nazwy - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Brak pliku
Toolbar: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000 -> Brak nazwy - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  Brak pliku

FireFox:
========
FF DefaultProfile: 73h4lfqh.default
FF ProfilePath: C:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\73h4lfqh.default [2017-09-07]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\73h4lfqh.default -> Bing
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\73h4lfqh.default -> Bing
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\73h4lfqh.default -> Bing
FF Homepage: Mozilla\Firefox\Profiles\73h4lfqh.default -> hxxps://www.youtube.com/
FF Session Restore: Mozilla\Firefox\Profiles\73h4lfqh.default -> [funkcja włączona]
FF Keyword.URL: Mozilla\Firefox\Profiles\73h4lfqh.default -> hxxp://www.bing.com/search?FORM=SK216DF&PC;=SK216&q;=
FF NetworkProxy: Mozilla\Firefox\Profiles\73h4lfqh.default -> type", 0
FF Extension: (Bing Search) - C:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\73h4lfqh.default\Extensions\[removed] [2017-05-27]
FF Extension: (Avast SafePrice) - C:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\73h4lfqh.default\Extensions\[removed] [2017-09-06]
FF Extension: (Avast Online Security) - C:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\73h4lfqh.default\Extensions\[removed] [2017-09-06]
FF Extension: (Adblock Plus) - C:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\73h4lfqh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-11]
FF Extension: (Firefox Screenshots) - C:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\73h4lfqh.default\features\{ce9ce1bc-7dce-4e43-ac79-e0e9f281a56d}\[removed] [2017-09-02]
FF SearchPlugin: C:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\73h4lfqh.default\searchplugins\bing-.xml [2017-05-28]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-14] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-04-07] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-14] ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2000-01-01] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2000-01-01] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-07-19] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-07-19] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-04-07] (Adobe Systems)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://mail.ru/cnt/10445?gp=811013
CHR StartupUrls: Default -> "hxxp://mail.ru/cnt/10445?gp=811013","hxxps://www.youtube.com/?gl=PL&hl;=pl"
CHR NewTab: Default ->  Not-active:"chrome-extension://oelpkepjlgmehajehfeicfbjdiobdkfj/visual-bookmarks.html"
CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/distib/ep/?q={searchTerms}&product;_id=%7B9DBEB58C-BE4C-4D0A-97F5-3F081E8D61D5%7D&gp;=811014
CHR DefaultSearchKeyword: Default -> mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/ff3?q={searchTerms}
CHR Profile: C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default [2017-09-06]
CHR Extension: (Brak nazwy) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe [2017-03-28]
CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof [2017-03-28]
CHR Extension: (Adblock Plus) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-09-06]
CHR Extension: (Adobe Acrobat) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-05]
CHR Extension: (Brak nazwy) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2017-06-11]
CHR Extension: (Auto Refresh) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifooldnmmcmlbdennkpdnlnbgbmfalko [2017-09-06]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-06]
CHR Extension: (Визуальные Закладки Mail.Ru) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj [2017-06-11]
CHR Extension: (Mail.Ru) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd [2017-09-06]
CHR Extension: (Chrome Media Router) - C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-06]
CHR HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [ccfifbojenkenpkmnbnndeadpfdiffof] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
CHR HKLM-x32\…\Chrome\Extension: [oelpkepjlgmehajehfeicfbjdiobdkfj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [ojlcebdkbpjdpiligkdbbkdkfjmchbfd] - hxxps://clients2.google.com/service/update2/crx

==================== Usługi (filtrowane) ====================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [694464 2016-04-07] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7452288 2017-09-06] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [275208 2017-09-06] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1536520 2017-05-16] ()
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [8163392 2017-07-14] (GOG.com)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [Brak podpisu cyfrowego]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-08-25] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2000-01-01] (Intel Corporation)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [163280 2015-05-18] (MSI)
R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [512960 2017-07-26] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [512960 2017-07-26] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-07-19] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-07-26] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2098528 2017-08-23] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2977640 2017-08-23] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-01-08] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2016-01-08] ()
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [56040 2015-11-19] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 GalaxyClientService; "C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe" [X]

===================== Sterowniki (filtrowane) ======================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [320528 2017-09-06] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198976 2017-09-06] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343296 2017-09-06] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57736 2017-09-06] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [104624 2017-09-06] (AVAST Software)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [47016 2017-09-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [147784 2017-09-06] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110376 2017-09-06] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84416 2017-09-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1016384 2017-09-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [590880 2017-09-06] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [199312 2017-09-06] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-09-06] (AVAST Software)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1x64.sys [28008 2015-08-31] (Windows (R) Win 7 DDK provider)
R3 DFX12; C:\Windows\System32\drivers\dfx12x64.sys [28344 2015-10-13] (Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 HPEWSFXBULK; C:\Windows\System32\drivers\hpfx64bulk.sys [20504 2009-02-26] (Hewlett Packard)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [22216 2014-05-27] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [22728 2014-05-27] ()
R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [25800 2014-05-27] ()
S3 ipadtst; C:\Program Files (x86)\MSI\Super Charger\ipadtst_64.sys [20464 2013-11-11] (Windows (R) Win 7 DDK provider)
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD.sys [44744 2014-05-27] ()
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2000-01-01] (Intel Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-07-26] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [48064 2017-07-26] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-07-26] (NVIDIA Corporation)
S3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [45928 2017-06-29] (SteelSeries ApS)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2017-09-07 17:40 - 2017-09-07 17:40 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-09-07 17:11 - 2017-05-24 19:29 - 000018513 _____ C:\Users\Grzegorz\Desktop\Bez tytułu 1.odt
2017-09-07 17:10 - 2017-09-07 17:10 - 000000000 ____D C:\Users\Grzegorz\Desktop\geografia szwecja
2017-09-07 17:07 - 2017-09-07 17:07 - 000000000 ____D C:\Users\Grzegorz\Desktop\militarny
2017-09-07 17:06 - 2017-09-07 17:06 - 000000000 ____D C:\Users\Grzegorz\Desktop\Nowy folder (2)
2017-09-07 17:06 - 2017-09-07 17:06 - 000000000 ____D C:\Users\Grzegorz\Desktop\Nowy folder
2017-09-07 17:06 - 2017-05-25 22:38 - 000001456 _____ C:\Users\Grzegorz\Desktop\ang vviguyyiu.txt
2017-09-07 17:06 - 2017-05-25 22:36 - 000019200 _____ C:\Users\Grzegorz\Desktop\ang ihbuybioutggv.odt
2017-09-07 17:06 - 2017-05-25 22:33 - 000019353 _____ C:\Users\Grzegorz\Desktop\ang ihbuybio.odt
2017-09-07 17:06 - 2017-05-24 19:53 - 013596067 _____ C:\Users\Grzegorz\Desktop\ang ngchckhgv,jgyh.odp
2017-09-07 17:06 - 2017-05-24 19:46 - 009895936 _____ C:\Users\Grzegorz\Desktop\angholiday.odp
2017-09-07 17:06 - 2017-05-24 19:33 - 010491390 _____ C:\Users\Grzegorz\Desktop\ang.pdf
2017-09-07 17:06 - 2017-05-24 19:06 - 013043008 _____ C:\Users\Grzegorz\Desktop\ang.odt
2017-09-06 21:33 - 2017-09-07 17:40 - 000000000 ____D C:\FRST
2017-09-06 19:48 - 2017-09-06 19:48 - 002395648 _____ (Farbar) C:\Users\Grzegorz\Desktop\FRST64.exe
2017-09-06 19:34 - 2017-09-07 17:31 - 000618194 _____ C:\Windows\ntbtlog.txt
2017-09-06 19:27 - 2017-09-06 19:24 - 000104624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2017-09-06 19:23 - 2017-09-06 19:23 - 000003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-09-06 19:23 - 2017-09-06 19:23 - 000001882 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-09-06 19:23 - 2017-09-06 19:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2017-09-06 19:23 - 2017-09-06 19:22 - 000590880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-09-06 19:23 - 2017-09-06 19:22 - 000361336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-09-06 19:23 - 2017-09-06 19:22 - 000199312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-09-06 19:23 - 2017-09-06 19:22 - 000147784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-09-06 19:23 - 2017-09-06 19:22 - 000084416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-09-06 19:22 - 2017-09-06 19:22 - 000401488 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-09-06 19:22 - 2017-09-06 19:22 - 000110376 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-09-06 19:22 - 2017-09-06 19:22 - 000047016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-09-06 19:22 - 2017-09-06 19:21 - 001016384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-09-06 19:22 - 2017-09-06 19:21 - 000343296 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-09-06 19:22 - 2017-09-06 19:21 - 000320528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-09-06 19:22 - 2017-09-06 19:21 - 000198976 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-09-06 19:22 - 2017-09-06 19:21 - 000057736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-09-06 19:20 - 2017-09-06 21:25 - 006654960 _____ (AVAST Software) C:\Users\Public\Desktop\avast_free_antivirus_setup_online.exe
2017-08-26 00:13 - 2017-08-27 15:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-08-19 16:26 - 2017-08-19 16:26 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_sshid_01011.Wdf
2017-08-17 23:05 - 2017-07-29 16:56 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-08-17 23:05 - 2017-07-21 16:26 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll
2017-08-17 23:05 - 2017-07-21 16:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll
2017-08-17 23:05 - 2017-07-15 20:35 - 000394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-08-17 23:05 - 2017-07-15 19:52 - 000346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2017-08-17 23:05 - 2017-07-14 17:29 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-08-17 23:05 - 2017-07-14 17:12 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-08-17 23:05 - 2017-07-14 17:12 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-08-17 23:05 - 2017-07-14 17:11 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-08-17 23:05 - 2017-07-14 17:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-08-17 23:05 - 2017-07-14 17:10 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-08-17 23:05 - 2017-07-14 17:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-08-17 23:05 - 2017-07-14 17:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-08-17 23:05 - 2017-07-14 16:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-08-17 23:05 - 2017-07-14 16:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-08-17 23:05 - 2017-07-14 16:57 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2017-08-17 23:05 - 2017-07-14 16:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2017-08-17 23:05 - 2017-07-14 16:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2017-08-17 23:05 - 2017-07-14 08:49 - 025733632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-08-17 23:05 - 2017-07-14 08:47 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-08-17 23:05 - 2017-07-14 08:45 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-08-17 23:05 - 2017-07-14 08:45 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-08-17 23:05 - 2017-07-14 08:44 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-08-17 23:05 - 2017-07-14 08:44 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-08-17 23:05 - 2017-07-14 08:38 - 002899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-08-17 23:05 - 2017-07-14 08:29 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-08-17 23:05 - 2017-07-14 08:28 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-08-17 23:05 - 2017-07-14 08:22 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-08-17 23:05 - 2017-07-14 08:20 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-08-17 23:05 - 2017-07-14 08:20 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-08-17 23:05 - 2017-07-14 08:19 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-08-17 23:05 - 2017-07-14 08:19 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-08-17 23:05 - 2017-07-14 08:08 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-08-17 23:05 - 2017-07-14 08:02 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-08-17 23:05 - 2017-07-14 07:49 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-08-17 23:05 - 2017-07-14 07:48 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-08-17 23:05 - 2017-07-14 07:47 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-08-17 23:05 - 2017-07-14 07:42 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-08-17 23:05 - 2017-07-14 07:40 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-08-17 23:05 - 2017-07-14 07:35 - 005981184 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-08-17 23:05 - 2017-07-14 07:35 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-08-17 23:05 - 2017-07-14 07:33 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-08-17 23:05 - 2017-07-14 07:16 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-08-17 23:05 - 2017-07-14 07:11 - 000725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-08-17 23:05 - 2017-07-14 07:10 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-08-17 23:05 - 2017-07-14 07:09 - 002132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-08-17 23:05 - 2017-07-14 07:09 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-08-17 23:05 - 2017-07-14 06:40 - 015254016 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-08-17 23:05 - 2017-07-14 06:23 - 003240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-08-17 23:05 - 2017-07-14 06:07 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-08-17 23:05 - 2017-07-14 05:58 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-08-17 23:05 - 2017-07-14 04:54 - 020270080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-08-17 23:05 - 2017-07-14 04:48 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-08-17 23:05 - 2017-07-14 04:48 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-08-17 23:05 - 2017-07-14 04:48 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-08-17 23:05 - 2017-07-14 04:48 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-08-17 23:05 - 2017-07-14 04:47 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-08-17 23:05 - 2017-07-14 04:44 - 002290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-08-17 23:05 - 2017-07-14 04:42 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-08-17 23:05 - 2017-07-14 04:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-08-17 23:05 - 2017-07-14 04:39 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-08-17 23:05 - 2017-07-14 04:38 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-08-17 23:05 - 2017-07-14 04:38 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-08-17 23:05 - 2017-07-14 04:38 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-08-17 23:05 - 2017-07-14 04:30 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-08-17 23:05 - 2017-07-14 04:26 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-08-17 23:05 - 2017-07-14 04:25 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-08-17 23:05 - 2017-07-14 04:25 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-08-17 23:05 - 2017-07-14 04:23 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-08-17 23:05 - 2017-07-14 04:22 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-08-17 23:05 - 2017-07-14 04:21 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-08-17 23:05 - 2017-07-14 04:20 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-08-17 23:05 - 2017-07-14 04:17 - 004546048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-08-17 23:05 - 2017-07-14 04:13 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-08-17 23:05 - 2017-07-14 04:12 - 000693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-08-17 23:05 - 2017-07-14 04:11 - 002057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-08-17 23:05 - 2017-07-14 04:11 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-08-17 23:05 - 2017-07-14 04:09 - 013663744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-08-17 23:05 - 2017-07-14 03:53 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-08-17 23:05 - 2017-07-14 03:50 - 001314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-08-17 23:05 - 2017-07-14 03:48 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-08-17 23:05 - 2017-07-08 17:34 - 000370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-08-17 23:05 - 2017-07-08 17:00 - 003224064 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-08-17 23:05 - 2017-07-07 17:37 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-08-17 23:05 - 2017-07-07 17:33 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-08-17 23:05 - 2017-07-07 17:33 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-08-17 23:05 - 2017-07-07 17:33 - 000363752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2017-08-17 23:05 - 2017-07-07 17:33 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-08-17 23:05 - 2017-07-07 17:33 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-08-17 23:05 - 2017-07-07 17:31 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:15 - 004001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-08-17 23:05 - 2017-07-07 17:15 - 003945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-08-17 23:05 - 2017-07-07 17:13 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-08-17 23:05 - 2017-07-07 17:11 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 17:02 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-08-17 23:05 - 2017-07-07 17:01 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-08-17 23:05 - 2017-07-07 17:01 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-08-17 23:05 - 2017-07-07 17:01 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-08-17 23:05 - 2017-07-07 16:58 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-08-17 23:05 - 2017-07-07 16:57 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-08-17 23:05 - 2017-07-07 16:54 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-08-17 23:05 - 2017-07-07 16:54 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-08-17 23:05 - 2017-07-07 16:54 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-08-17 23:05 - 2017-07-07 16:53 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-08-17 23:05 - 2017-07-07 16:53 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-08-17 23:05 - 2017-07-07 16:51 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-08-17 23:05 - 2017-07-07 16:48 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-08-17 23:05 - 2017-07-07 16:48 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-08-17 23:05 - 2017-07-07 16:48 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-08-17 23:05 - 2017-07-07 16:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-08-17 23:05 - 2017-07-07 16:47 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 16:47 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 16:47 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-08-17 23:05 - 2017-07-07 16:47 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000144896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-08-17 23:05 - 2017-07-01 15:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll
2017-08-17 23:04 - 2017-07-21 16:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexch40.dll
2017-08-17 23:04 - 2017-07-21 16:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2017-08-17 23:04 - 2017-07-14 09:16 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-08-17 23:04 - 2017-07-14 09:15 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-08-17 23:04 - 2017-07-14 05:01 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-08-17 23:04 - 2017-07-07 17:29 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-08-17 23:04 - 2017-07-07 17:29 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-08-17 23:04 - 2017-07-07 17:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-08-17 23:04 - 2017-07-07 17:29 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-08-17 23:04 - 2017-07-07 17:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-08-17 23:04 - 2017-07-07 17:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-08-17 23:04 - 2017-07-07 17:10 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-08-17 23:04 - 2017-07-07 17:10 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-08-17 23:04 - 2017-07-07 17:10 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-08-17 23:04 - 2017-07-07 17:10 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-08-17 23:04 - 2017-07-07 17:10 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-08-17 23:04 - 2017-07-07 16:48 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2017-09-07 17:38 - 2016-11-18 16:11 - 000000000 ____D C:\Users\Grzegorz\AppData\LocalLow\Mozilla
2017-09-07 17:38 - 2016-01-05 17:42 - 000000000 ____D C:\ProgramData\NVIDIA
2017-09-07 17:37 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-07 17:32 - 2011-02-04 19:55 - 000741152 _____ C:\Windows\system32\perfh015.dat
2017-09-07 17:32 - 2011-02-04 19:55 - 000156224 _____ C:\Windows\system32\perfc015.dat
2017-09-07 17:32 - 2009-07-14 07:13 - 001672684 _____ C:\Windows\system32\PerfStringBackup.INI
2017-09-07 17:32 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2017-09-07 17:28 - 2009-07-14 06:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-07 17:28 - 2009-07-14 06:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-06 21:29 - 2016-10-09 10:12 - 000000000 ____D C:\AdwCleaner
2017-09-06 19:28 - 2016-05-02 23:36 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-09-06 19:28 - 2016-05-02 23:36 - 000000000 ____D C:\ProgramData\Skype
2017-09-06 19:25 - 2017-07-17 18:46 - 000000000 ____D C:\Users\Grzegorz\AppData\Local\osu!
2017-09-06 19:22 - 2017-06-11 14:23 - 000000000 ____D C:\ProgramData\AVAST Software
2017-09-05 20:04 - 2016-01-05 18:06 - 000000000 ____D C:\Users\Grzegorz\AppData\Roaming\Origin
2017-09-05 20:04 - 2016-01-05 18:02 - 000000000 ____D C:\ProgramData\Origin
2017-09-05 14:46 - 2017-08-06 19:45 - 000000681 _____ C:\Users\Public\Desktop\Battlefield 1.lnk
2017-09-01 11:34 - 2016-05-27 14:06 - 000000000 ____D C:\Users\Grzegorz\Desktop\muzyka
2017-08-31 23:58 - 2017-05-24 14:47 - 000001241 _____ C:\Users\Grzegorz\Desktop\nativelog.txt
2017-08-31 23:22 - 2017-05-18 11:46 - 000000000 ____D C:\Users\Grzegorz\AppData\Roaming\.minecraft
2017-08-31 04:00 - 2016-10-07 18:57 - 000000000 ____D C:\Users\Grzegorz\AppData\Roaming\Riot Games
2017-08-31 01:17 - 2017-05-03 13:32 - 000000000 ____D C:\Users\Grzegorz\AppData\Local\Spotify
2017-08-31 01:17 - 2016-09-30 20:56 - 000000000 ____D C:\Program Files (x86)\Steam
2017-08-30 22:54 - 2016-09-06 22:58 - 000000000 ____D C:\Users\Grzegorz\Desktop\background
2017-08-30 22:00 - 2017-05-03 13:32 - 000000000 ____D C:\Users\Grzegorz\AppData\Roaming\Spotify
2017-08-30 11:03 - 2016-01-05 18:01 - 000000000 ____D C:\Program Files (x86)\Origin
2017-08-27 21:59 - 2016-01-23 14:44 - 000000000 ____D C:\Users\Grzegorz\AppData\Roaming\uTorrent
2017-08-27 21:58 - 2016-06-19 22:26 - 000000000 ____D C:\Users\Grzegorz\AppData\Local\CrashDumps
2017-08-27 15:37 - 2016-10-09 08:49 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-08-24 21:07 - 2017-02-03 22:54 - 000002201 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-24 01:22 - 2016-01-05 16:51 - 001644354 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-08-18 10:46 - 2016-09-11 22:18 - 000000000 ____D C:\Users\Grzegorz\AppData\Roaming\GG
2017-08-18 10:44 - 2009-07-14 06:45 - 000300864 _____ C:\Windows\system32\FNTCACHE.DAT
2017-08-14 18:41 - 2017-06-11 14:19 - 000000000 ____D C:\Windows\system32\MRT
2017-08-14 18:37 - 2017-06-13 00:39 - 140394280 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-08-14 18:35 - 2016-11-25 15:41 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-08-14 18:35 - 2016-11-25 15:41 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-08-14 18:35 - 2016-11-25 15:41 - 000004412 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-08-14 18:35 - 2016-11-25 15:41 - 000000000 ____D C:\Windows\system32\Macromed
2017-08-14 18:35 - 2016-10-31 11:46 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-08-14 18:27 - 2016-01-05 17:42 - 000000000 ____D C:\Users\Grzegorz\AppData\Local\NVIDIA Corporation

==================== Pliki w katalogu głównym wybranych folderów =======

2016-01-13 18:21 - 2016-01-13 18:21 - 000000000 ___SH () C:\Users\Grzegorz\AppData\Local\LumaEmu
2016-09-03 10:53 - 2016-09-03 10:53 - 000000017 _____ () C:\Users\Grzegorz\AppData\Local\resmon.resmoncfg
2017-05-24 13:52 - 2017-05-24 13:52 - 000000057 _____ () C:\ProgramData\Ament.ini
2016-01-05 16:55 - 2016-01-05 16:55 - 000000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap ======================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo
C:\Windows\explorer.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo
C:\Windows\system32\services.exe => Plik podpisany cyfrowo
C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo

LastRegBack: 2017-09-02 17:19

==================== Koniec  FRST.txt ============================

Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 20-08-2017
Uruchomiony przez Grzegorz (07-09-2017 17:42:53)
Uruchomiony z E:\
Windows 7 Ultimate Service Pack 1 (X64) (2016-01-05 14:46:15)
Tryb startu: Normal
==========================================================


==================== Konta użytkowników: =============================

Administrator (S-1-5-21-3841648094-4281997214-1728550566-500 - Administrator - Disabled)
dmyybbizl (S-1-5-21-3841648094-4281997214-1728550566-1003 - Limited - Disabled)
Gość (S-1-5-21-3841648094-4281997214-1728550566-501 - Limited - Enabled)
Grzegorz (S-1-5-21-3841648094-4281997214-1728550566-1000 - Administrator - Enabled) => C:\Users\Grzegorz
HomeGroupUser$ (S-1-5-21-3841648094-4281997214-1728550566-1002 - Limited - Enabled)

==================== Centrum zabezpieczeń ========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Zainstalowane programy ======================

(W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.)

µTorrent (HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\uTorrent) (Version: 3.5.0.43916 - BitTorrent Inc.)
A3Launcher version 0.1.5.5 (HKLM-x32\…\{1E29A86E-9AE2-4CD8-74C8-6B170ED3C4D2}_is1) (Version: 0.1.5.5 - Maca134)
Adobe Acrobat Reader DC - Polish (HKLM-x32\…\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 17.009.20058 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\…\Adobe Creative Cloud) (Version: 3.6.0.248 - Adobe Systems Incorporated)
Adobe Flash Player 26 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 26.0.0.151 - Adobe Systems Incorporated)
Aktualizacje NVIDIA 27.1.0.0 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 27.1.0.0 - NVIDIA Corporation) Hidden
Ansel (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 384.94 - NVIDIA Corporation) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{E92BB800-BCC5-4C25-8102-AC2C3B7C7C1E}) (Version: 5.5 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{9C912B1E-06DD-43EF-BB2B-45CB2C88BAAE}) (Version: 5.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{0A596141-97D5-45FA-9281-98DFAF48D579}) (Version: 10.3.2.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Arma 3 (HKLM\…\Steam App 107410) (Version:  - Bohemia Interactive)
Avast Free Antivirus (HKLM-x32\…\Avast Antivirus) (Version: 17.6.2310 - AVAST Software)
Azure AD Authentication Connected Service (HKLM-x32\…\{3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (HKLM-x32\…\{1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2}) (Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Badanie mające na celu poprawę produktów HP Deskjet 1510 series (HKLM\…\{201842BD-6AB0-422A-9A01-DD1DA9BC03B9}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Battlefield 3™ (HKLM-x32\…\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlefield 4™ (HKLM-x32\…\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts)
Battlefield™ 1 (HKLM-x32\…\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.50.62815 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\…\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB)
Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\…\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Borderlands 2 (HKLM\…\Steam App 49520) (Version:  - Gearbox Software)
Borderlands 2 (HKLM-x32\…\Steam App 49520) (Version:  - Gearbox Software)
CCleaner (HKLM\…\CCleaner) (Version: 5.22 - Piriform)
CL-Eye Driver (HKLM-x32\…\CL-Eye Driver) (Version: 5.3.0.0341 - Code Laboratories, Inc.)
Crossout Launcher 1.0.3.18 (HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\CrossOutLauncher_is1) (Version:  - )
Dotfuscator and Analytics Community Edition 5.19.0 (HKLM-x32\…\{4C5B1DD0-7E8E-4972-9247-818E6D030552}) (Version: 5.19.0.2930 - PreEmptive Solutions) Hidden
Dying Light (HKLM\…\Steam App 239140) (Version:  - Techland)
Dying Light (HKLM-x32\…\Steam App 239140) (Version:  - Techland)
ESN Sonar (HKLM-x32\…\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
Evolve Stage 2 (HKLM\…\Steam App 273350) (Version:  - Turtle Rock Studios)
Fallout 4 (wersja 1.8.7) (HKLM-x32\…\Fallout 4_is1) (Version: 1.8.7 - [removed])
Far Cry 4 (HKLM-x32\…\Uplay Install 420) (Version:  - Ubisoft)
Far Cry Primal (HKLM-x32\…\Uplay Install 2010) (Version:  - Ubisoft)
GG (HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\GG) (Version: 12 - GG Network S.A.)
GOG Galaxy (HKLM-x32\…\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 60.0.3112.113 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.115 - Google Inc.) Hidden
HP Deskjet 1510 series — podstawowe oprogramowanie urządzenia (HKLM\…\{021AA127-6B6D-46EF-9697-5089FA686FB6}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Deskjet 1510 series Pomoc (HKLM-x32\…\{065AAC3B-F0A7-4D13-A40B-3133D319E4EB}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.0.1001 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\…\{4188E70A-4D3B-447C-B366-963C9E8B4538}) (Version: 5.0.10.2907 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.5.69 - Intel Corporation)
IP Camera Adapter (HKLM-x32\…\{6D140BFF-7CC5-4BFE-AD6D-47035FFE5F14}) (Version: 2.0.0.0 - Pavel Khlebovich)
iTunes (HKLM\…\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Java 8 Update 131 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
League of Legends (HKLM-x32\…\{EA8630BD-0DCC-4154-B972-AAA6C8989E1A}) (Version: 4.2.1 - Riot Games) Hidden
League of Legends (HKLM-x32\…\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games)
Lightworks (HKLM-x32\…\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 12.6.0.0 - Lightworks)
MegaDownloader 1.7 (HKLM\…\{C12C2297-65A4-4E64-9AE1-29F0D947FDA0}}_is1) (Version: 1.7 - AppsForMega.info)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\…\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\…\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\…\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\…\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\…\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\…\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\…\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\…\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\…\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\…\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (Polski) (HKLM-x32\…\{A9D7F21C-C602-46C5-A080-4E44E440F249}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\…\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\…\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 z dodatkiem Targeting Pack (Polski) (HKLM-x32\…\{EDC3FD45-C9CE-483F-8013-D18C69EF3F85}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.7 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft .NET Framework 4.7 (Polski) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\…\Microsoft Help Viewer 2.2) (Version: 2.2.24720 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\…\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (x64) (HKLM\…\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom  (HKLM\…\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service  (HKLM-x32\…\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\…\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\…\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\…\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\…\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\…\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2015 Tools for Unity (HKLM-x32\…\{F0DB2786-18C8-4B0D-9DC2-BA58856A2821}) (Version: 2.1.0.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 with Update 1 (HKLM-x32\…\{1d03ad7c-fa27-4517-91b0-410bb49f94d9}) (Version: 14.0.24720.1 - Microsoft Corporation)
Microsoft Windows Media Video 9 VCM (HKLM-x32\…\WMV9_VCM) (Version:  - )
Minecraft (HKLM-x32\…\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Mirror's Edge™ Catalyst (HKLM-x32\…\{12228a0d-f6ad-4691-82af-d2c643424468}) (Version: 1.0.3.47248 - Electronic Arts)
Mozilla Firefox 55.0.3 (x86 pl) (HKLM-x32\…\Mozilla Firefox 55.0.3 (x86 pl)) (Version: 55.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 55.0.3.6445 - Mozilla)
MSBuild/NuGet Integration 14.0 (x86) (HKLM-x32\…\{FA0599C5-C083-41BE-8AEA-E8EB9070D128}) (Version: 14.0.24720 - Microsoft Corporation) Hidden
MSI Super Charger (HKLM-x32\…\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.029 - MSI)
Multi-Device Hybrid Apps using C# - Templates - ENU (HKLM-x32\…\{12D99739-FFD3-3761-8AA6-F929E0FE407E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Nexus Mod Manager (HKLM\…\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.63.14 - Black Tree Gaming)
NVIDIA GeForce Experience 3.8.0.89 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.8.0.89 - NVIDIA Corporation)
NVIDIA Oprogramowanie systemu PhysX 9.17.0524 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
NVIDIA Sterownik 3D Vision 384.94 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 384.94 - NVIDIA Corporation)
NVIDIA Sterownik dźwięku HD 1.3.34.27 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.27 - NVIDIA Corporation)
NVIDIA Sterownik graficzny 384.94 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 384.94 - NVIDIA Corporation)
NVIDIA Sterownik kontrolera 3D Vision 369.04 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NvvHci (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
OpenOffice 4.1.2 (HKLM-x32\…\{E0ED9630-38E3-418F-A615-A9B2B5758BE5}) (Version: 4.12.9782 - Apache Software Foundation)
Oprogramowanie mikroukładu Intel® (HKLM-x32\…\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Origin (HKLM-x32\…\Origin) (Version: 10.5.2.49155 - Electronic Arts, Inc.)
osu! (HKLM-x32\…\{98893c65-6cad-4e83-aced-c7218d3a9953}) (Version: latest - ppy Pty Ltd)
Panel sterowania NVIDIA 384.94 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 384.94 - NVIDIA Corporation) Hidden
PreEmptive Analytics Visual Studio Components (HKLM-x32\…\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}) (Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.92.115.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7806 - Realtek Semiconductor Corp.)
Roslyn Language Services - x86 (HKLM-x32\…\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (HKLM-x32\…\{7E0DDE7A-9EC6-3672-AC92-08DA2C292DB7}) (Version: 14.0.24723 - Microsoft Corporation) Hidden
Skype Click to Call (HKLM-x32\…\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.40 (HKLM-x32\…\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
Skyrim Script Extender (SKSE) (HKLM\…\Steam App 365720) (Version:  - The SKSE Team)
Smart-X7 7.80 (HKLM\…\WheelMouse) (Version:  - )
Spotify (HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Spotify) (Version: 1.0.60.492.gbb40dab8 - Spotify AB)
Star Conflict Launcher 1.0.1.76 (HKLM-x32\…\StarConflictLauncher_is1) (Version:  - )
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Team Explorer for Microsoft Visual Studio 2015 (HKLM-x32\…\{48992F68-BEE6-35D8-89AC-6A81406F1096}) (Version: 14.0.24712 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (HKLM-x32\…\{9EABBFE1-7EED-47D9-8FB8-21D7E4808057}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
The Elder Scrolls V: Skyrim (HKLM\…\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 3: Wild Hunt (HKLM\…\Steam App 292030) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (HKLM-x32\…\{7FBEE165-A653-4B2A-A93A-4643794E22A8}) (Version: 1.7.4.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (HKLM-x32\…\{D7C8A95B-B1EE-43B1-837D-C73D1321FEBA}) (Version: 1.7.4.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.7.4.0 (HKLM-x32\…\{33e2204a-4ec6-4458-895a-47e2a404d990}) (Version: 1.7.24720.0 - Microsoft Corporation)
Unturned (HKLM\…\Steam App 304930) (Version:  - Smartly Dressed Games)
Update for  (KB2504637) (HKLM-x32\…\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\…\Uplay) (Version: 22.2 - Ubisoft)
VGA Boost (HKLM-x32\…\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.8 - MSI)
Visual Studio 2015 Update 1 (KB3022398) (HKLM-x32\…\{fcaa9dba-9438-48b6-ad91-4e9b4cc7084a}) (Version: 14.0.24720 - Microsoft Corporation)
VS Update core components (HKLM-x32\…\{5F7870A1-0586-313E-A9FF-3249DCE9F63A}) (Version: 14.0.24720 - Microsoft Corporation) Hidden
Vulkan Run Time Libraries 1.0.42.1 (HKLM\…\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.)
War Thunder (HKLM\…\Steam App 236390) (Version:  - Gaijin Entertainment)
WCF Data Services 5.6.4 Runtime (HKLM-x32\…\{DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (HKLM-x32\…\{0A3B508E-5638-4471-BCC9-954E1868CB86}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WinRAR 5.21 (64-bitowy) (HKLM\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)

==================== Niestandardowe rejestracje CLSID (filtrowane): ==========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

CustomCLSID: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\Grzegorz\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.)
CustomCLSID: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-04-01] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-04-01] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-04-01] ()
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-06] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers1: [AccExt] -> [CC]{2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} =>  -> Brak pliku
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-06] (AVAST Software)
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-03-11] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-03-11] (Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-06] (AVAST Software)
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers5: [DreamScene] -> {BE800AEB-A440-4B63-94CD-AA6B43647DF9} => C:\Windows\System32\DreamScene.dll [2016-09-06] (Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-07-19] (NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-04-01] ()
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-06] (AVAST Software)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-03-11] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-03-11] (Alexander Roshal)
ContextMenuHandlers1_S-1-5-21-3841648094-4281997214-1728550566-1000: [GGDriveMenu] -> [CC]{E68D0A55-3C40-4712-B90D-DCFA93FF2534} =>  -> Brak pliku
ContextMenuHandlers4_S-1-5-21-3841648094-4281997214-1728550566-1000: [GGDriveMenu] -> {E68D0A55-3C40-4712-B90D-DCFA93FF2534} => C:\Users\Grzegorz\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll [2014-03-20] (GG Network S.A.)
ContextMenuHandlers5_S-1-5-21-3841648094-4281997214-1728550566-1000: [GGDriveMenu] -> {E68D0A55-3C40-4712-B90D-DCFA93FF2534} => C:\Users\Grzegorz\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll [2014-03-20] (GG Network S.A.)

==================== Zaplanowane zadania (filtrowane) =============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

Task: {069A0657-3BAE-45AF-9A6B-AA61A1E4DF8D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-26] (Piriform Ltd)
Task: {1313A766-D6A0-48B0-9F7B-F298B4E7F66D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {18264AC1-6B88-4DF7-859B-FA2A6F7107EE} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-07-26] (NVIDIA Corporation)
Task: {3368C582-22B5-4728-8A1A-5AF8E7FF64BF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-03] (Google Inc.)
Task: {506EA7DB-2114-4C78-9747-D2C166B5B8E4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-08-14] (Adobe Systems Incorporated)
Task: {577D5EC0-5A53-4B16-A918-C3330E9FB849} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-07-26] (NVIDIA Corporation)
Task: {805C6185-1E27-49B0-8C99-5BF227CF2378} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {871FB9D0-FC4D-40F5-BFB9-56D72C3A6C3B} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [2016-01-06] (Symantec Corporation)
Task: {95165F7C-ABD4-4AE6-918B-BEBF6DECF289} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-07-26] (NVIDIA Corporation)
Task: {A5BC9654-5D70-446A-972E-539878D399E9} - System32\Tasks\HPCustParticipation HP Deskjet 1510 series => C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
Task: {A9E9471B-40E0-41E9-8282-0044B9F95C82} - System32\Tasks\Microsoft\Windows\PLA\cpu => C:\Windows\system32\rundll32.exe C:\Windows\system32\pla.dll,PlaHost "cpu" "$(Arg0)"
Task: {B31B38F9-778A-444F-A50E-D5DDE1CE9D16} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-07-26] (NVIDIA Corporation)
Task: {B9E90955-6962-4D58-811E-C76D26A78277} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-09-06] (AVAST Software)
Task: {BA88FDE6-2A92-40FE-A8C9-13E05C3FE8BD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-03] (Google Inc.)
Task: {BC299D95-C683-491F-8E34-33C002FCCD75} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-07-26] (NVIDIA Corporation)
Task: {C9681CA7-FCFE-43E1-AA4C-CBC9791D4701} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-07-26] (NVIDIA Corporation)
Task: {E3C0486C-92D8-45AC-B948-3EEAD0315278} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-07-26] (NVIDIA Corporation)
Task: {FCF14FE7-94B7-41EC-B8F5-FFCF8E03DDE2} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-07-26] (NVIDIA Corporation)

(Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.)


==================== Skróty & WMI ========================

(Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.)


==================== Załadowane moduły (filtrowane) ==============

2016-04-01 23:18 - 2016-04-01 23:18 - 000426160 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2016-08-26 20:25 - 2016-08-26 20:25 - 000065536 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll
2017-05-09 00:44 - 2017-05-09 00:44 - 001354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-10-05 19:17 - 2016-10-05 19:17 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-08-25 17:01 - 2014-08-25 17:01 - 000209712 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2014-08-25 17:01 - 2014-08-25 17:01 - 000057648 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2014-08-25 17:01 - 2014-08-25 17:01 - 000037168 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll
2014-08-25 17:01 - 2014-08-25 17:01 - 000057648 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTEncryptionCheck.dll
2017-08-06 20:17 - 2017-07-26 19:05 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-01-06 14:40 - 2016-01-08 19:39 - 000076152 _____ () C:\Windows\system32\PnkBstrA.exe
2017-09-06 19:22 - 2017-09-06 19:22 - 000067408 _____ () C:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000169832 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll
2017-09-06 19:22 - 2017-09-06 19:22 - 000824944 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000286712 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000059040 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000167096 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000211904 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000241960 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000149568 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll
2017-09-06 19:24 - 2017-09-06 19:24 - 005897648 _____ () C:\Program Files\AVAST Software\Avast\defs\17090604\algo.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000685688 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000241448 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2017-09-06 19:22 - 2017-09-06 19:22 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-09-06 19:21 - 2017-09-06 19:21 - 000233768 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-08-06 20:17 - 2017-07-26 19:04 - 069820864 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2017-08-06 20:17 - 2017-07-26 19:05 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-09-10 00:16 - 2000-01-01 02:00 - 001242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (filtrowane) =========

(Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.)

AlternateDataStreams: C:\Users\Grzegorz:Heroes & Generals [38]

==================== Tryb awaryjny (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.)


==================== Powiązania plików (filtrowane) ===============

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.)


==================== Internet Explorer - Witryny zaufane i z ograniczeniami ===============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.)


==================== Hosts - zawartość: ==========================

(Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.)

2009-07-14 04:34 - 2016-03-20 11:13 - 000000971 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       down.baidu2016.com
127.0.0.1       123.sogou.com
127.0.0.1       www.czzsyzgm.com
127.0.0.1       www.czzsyzxl.com

==================== Inne obszary ============================

(Obecnie brak automatycznej naprawy dla tej sekcji.)

HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Grzegorz\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.8.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Zapora systemu Windows [funkcja włączona]

==================== MSCONFIG/TASK MANAGER - Wyłączone elementy ==

MSCONFIG\startupfolder: C:^Users^Grzegorz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MEGAsync.lnk => C:\Windows\pss\MEGAsync.lnk.Startup
MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" –showwindow=false –onOSstartup=true
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: BingSvc => C:\Users\Grzegorz\AppData\Local\Microsoft\BingSvc\BingSvc.exe
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
MSCONFIG\startupreg: Gaijin.Net Agent => "C:\Users\Grzegorz\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe"
MSCONFIG\startupreg: GalaxyClient => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe /launchViaAutoStart
MSCONFIG\startupreg: GoogleChromeAutoLaunch_0A2C082D75BD86A8C9D324A42FDAB61F => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" –no-startup-window
MSCONFIG\startupreg: IAStorIcon => "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: ISCT Tray => C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: RTHDVCPL => "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
MSCONFIG\startupreg: ShadowPlay => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Spotify => "C:\Users\Grzegorz\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
MSCONFIG\startupreg: Spotify Web Helper => C:\Users\Grzegorz\AppData\Roaming\Spotify\SpotifyWebHelper.exe –autostart
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Super Charger => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
MSCONFIG\startupreg: uTorrent => "C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: WheelMouse => C:\Program Files\Mouse\Amoumain.exe

==================== Reguły Zapory systemu Windows (filtrowane) ===============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

FirewallRules: [{7C8F0C8B-A243-41D3-9B54-B5ACF75AEA8C}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
FirewallRules: [{5DD15977-D6C8-4A14-8CC5-ABBEB667B10F}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
FirewallRules: [{3FA18F86-07A6-4409-A2EF-706D36E515D6}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe
FirewallRules: [{7E131B7D-767D-4B1F-A650-4C6EAD8E881E}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe
FirewallRules: [{D2EF3EA1-6D75-4775-AB09-370BD03C4EFE}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe
FirewallRules: [{5F53AF07-8B5D-42EB-80D1-3397E2712EFF}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe
FirewallRules: [{A2A2618C-B1FB-4422-8356-5447CFA47D42}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C1D3EBBF-8CF6-4088-867A-74F30F21A9E7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{D7D0491C-B463-4C82-8B27-55FAA78DBFD2}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{A7C60697-A7BB-4EC4-BAFD-E8A08B4B8394}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{BE63F710-BB28-47AF-B186-4EA76FA1AB92}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{B831E87C-5315-41D6-B4B2-B8BC235BB3DC}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{00A98A21-34FB-485A-A48B-A161C1259A31}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{F2FC164C-CAE4-4EC2-A322-8E525154A419}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{69E4C003-097B-4C57-AA88-B26EFB34CB54}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngsteamlauncher.exe
FirewallRules: [{AC36254C-9E4D-4915-9943-BF202DD93BC6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngsteamlauncher.exe
FirewallRules: [{DB1893E2-75B7-4125-ADD5-D71626022EB4}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{B4E77EDC-B7A6-4DDF-BA42-76BE82DFD6A5}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio Tools for Unity\2015\UnityVS.OpenFile.exe
FirewallRules: [{8B06E549-95D4-4D88-92E4-AD0ACE48BA2C}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{F7D5E8F2-F9D7-4285-9897-B2BEF1133CC1}] => (Allow) C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{B5984167-1100-4A39-989E-4E1925178784}] => (Allow) C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{182E7E07-AE8C-4430-BDB1-CAA35AF6EC8A}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe
FirewallRules: [UDP Query User{71814763-A6B0-49C4-A865-B41494C4F2C8}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe
FirewallRules: [{0BA48CAB-8A0A-466D-BCA5-F546836FDC53}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{4A3D08A5-62D6-4514-B491-A1281B76AA95}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe
FirewallRules: [UDP Query User{D30426E1-7C64-4C2D-8644-D868A5C338D4}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe
FirewallRules: [{988299D1-9E3C-4CB8-B457-E225B42F85DB}] => (Allow) D:\Far Cry Primal\bin\FCPrimal.exe
FirewallRules: [{6406BF1B-1EFA-48B7-9694-1FBA9534D067}] => (Allow) D:\FarCry 4\bin\FarCry4.exe
FirewallRules: [{C3C59CEE-B952-4259-9A8A-A81E8471D103}] => (Allow) D:\FarCry 4\bin\FarCry4.exe
FirewallRules: [{5BE0CD50-5E04-43CE-9094-0FA2A15CA691}] => (Allow) D:\FarCry 4\bin\IGE_WPF64.exe
FirewallRules: [{237F7FF1-06D3-4A20-851F-C0265C8F932E}] => (Allow) D:\FarCry 4\bin\IGE_WPF64.exe
FirewallRules: [{B2C36EFA-1801-4E0D-958D-B5D529C21C95}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D6217A58-C274-4DF9-AAF3-0943B26056F5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{5BCAFE1C-698D-41F6-8ECE-3C5F81BBEEB9}D:\star conflict\launcher.exe] => (Allow) D:\star conflict\launcher.exe
FirewallRules: [UDP Query User{1FAB08C3-08F3-411A-BACB-98892DC5847A}D:\star conflict\launcher.exe] => (Allow) D:\star conflict\launcher.exe
FirewallRules: [{0D8050A6-D95A-45B7-B7C7-C25063A2A137}] => (Block) D:\star conflict\launcher.exe
FirewallRules: [{F776A411-938A-4268-B904-4112DEE0C8A5}] => (Block) D:\star conflict\launcher.exe
FirewallRules: [{F7C262F2-588E-4006-A917-D15DB37DDD62}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dying Light\DyingLightGame.exe
FirewallRules: [{F9A836E3-D0F8-43B6-AC2D-7E1ADB8EC1AC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dying Light\DyingLightGame.exe
FirewallRules: [{D24BA8CD-3C69-4007-8DAB-92ABF483A37F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{51F7AEDA-CF4A-4035-BC61-B031CBC2224F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{A539DB95-C947-4A87-A45D-F4D4BCA5254C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{8CBB6E62-0318-4FDD-AC0D-097929954D4F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C765B324-4E76-4FB9-A516-0F5C179BF389}] => (Allow) C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A540DB6A-814B-410B-82FA-36EA901F3DD2}] => (Allow) C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{1E4541D2-1132-4D83-B7CC-8166466F6FF8}] => (Allow) C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{2B450275-49D2-4783-BF94-25D29AD1C45D}] => (Allow) C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{55A4FEAB-0D01-4217-8AA9-38E8C29B2D03}] => (Allow) C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{42A10A35-AEFB-4A9B-BCE6-A76BAB31D9F9}] => (Allow) C:\Users\Grzegorz\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BA048215-9C22-4F49-AE79-6C93FEFD4411}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
FirewallRules: [{25284D6F-E7FF-4350-A2A4-C33BA863BF65}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
FirewallRules: [{078EA16C-C7D0-496E-A898-DAA346F803D3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A68EA510-4BD2-4522-AA47-5025B16F0C29}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3D1B9A59-0A42-4F92-BE03-1E7699C79127}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{21A6274F-EB68-447A-988A-85A4ECE02B5B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A853DC69-4FA4-407F-A4C6-15BA94B8AF7E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{1DA4F5FE-B6D8-40E9-9218-400E247D3A8E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill Test Server\LaunchPad.exe
FirewallRules: [{8873093D-8344-4602-9FDD-E29F96409F2C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill Test Server\LaunchPad.exe
FirewallRules: [{5ECD9B8A-C44F-409A-8B21-BCDE63EF4C5C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [{336D7143-9E87-48D1-A7BC-3AF49AE93050}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [{B60EE916-586F-4965-B1B8-DA35D2183F80}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{5A06C479-4CFC-47D3-9521-D4C18C7E324D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{E1ECA6B2-7F31-4A61-858D-4C5A604582BA}C:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Block) C:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [UDP Query User{6C2DA6DB-DA2E-4AF3-9FD9-1050D1AE6B62}C:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Block) C:\program files (x86)\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [{B5780E37-8D62-4557-896E-BBCCE1EA9AFC}] => (Allow) D:\Games\skyrim\steamapps\common\War Thunder\launcher.exe
FirewallRules: [{BEDEC448-EB56-49AE-A61B-EE3A0C14BCBF}] => (Allow) D:\Games\skyrim\steamapps\common\War Thunder\launcher.exe
FirewallRules: [TCP Query User{3256D16C-1525-482E-A88C-AF813BBAD11A}D:\games\skyrim\steamapps\common\war thunder\win64\aces.exe] => (Allow) D:\games\skyrim\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [UDP Query User{DA959A0A-FE36-48F5-9648-72CBD2EACBB8}D:\games\skyrim\steamapps\common\war thunder\win64\aces.exe] => (Allow) D:\games\skyrim\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [{A26D4865-952C-461A-B6A5-EEBEF3541C28}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
FirewallRules: [{607E263D-97DB-4921-B968-1E3F86C84B54}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
FirewallRules: [{DFBADA83-AFFF-4274-B04D-DF420790DD84}] => (Allow) D:\Origin Games\Battlefield 4\BFLauncher.exe
FirewallRules: [{BC81605A-E82F-46ED-BE98-54FFE6AD3448}] => (Allow) D:\Origin Games\Battlefield 4\BFLauncher.exe
FirewallRules: [{14EF47AA-AF9D-4D1C-BA78-EE4047869B2F}] => (Allow) D:\Origin Games\Battlefield 4\BFLauncher_x86.exe
FirewallRules: [{CED075CE-C47D-4A38-98DB-3D07BB567F72}] => (Allow) D:\Origin Games\Battlefield 4\BFLauncher_x86.exe
FirewallRules: [TCP Query User{4B6BD29D-0C34-4762-ABBE-C11846B93659}D:\origin games\battlefield 4\bf4.exe] => (Allow) D:\origin games\battlefield 4\bf4.exe
FirewallRules: [UDP Query User{AB584456-F6F2-445F-96E2-FE94BF0EABA2}D:\origin games\battlefield 4\bf4.exe] => (Allow) D:\origin games\battlefield 4\bf4.exe
FirewallRules: [{BEC2BB2B-C130-47FB-BE33-FC8D7D413839}] => (Allow) D:\Games\skyrim\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{90B34DCB-5C4D-4DD9-BB12-32FDF92AEAD6}] => (Allow) D:\Games\skyrim\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [TCP Query User{D3D00EFB-E8A0-4A84-9DA5-61A2E1F4BE63}D:\games\skyrim\steamapps\common\arma 3\arma3_x64.exe] => (Allow) D:\games\skyrim\steamapps\common\arma 3\arma3_x64.exe
FirewallRules: [UDP Query User{5AA551EF-D1DC-4FE9-8877-612409FD3339}D:\games\skyrim\steamapps\common\arma 3\arma3_x64.exe] => (Allow) D:\games\skyrim\steamapps\common\arma 3\arma3_x64.exe
FirewallRules: [{33ABC870-F679-4312-8C5D-1CF3004188A5}] => (Allow) D:\Games\skyrim\steamapps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{868EC11C-1250-4882-B206-C42665DBF83C}] => (Allow) D:\Games\skyrim\steamapps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{EC3EDCD9-BE0D-4439-BD3F-8D1B4B15814E}] => (Allow) D:\Games\skyrim\steamapps\common\The Witcher 3\bin\x64\witcher3.exe
FirewallRules: [{8B837234-B8A3-436C-B1C6-C1139B7A80B0}] => (Allow) D:\Games\skyrim\steamapps\common\The Witcher 3\bin\x64\witcher3.exe
FirewallRules: [TCP Query User{44D95E7D-8F19-4C49-8437-174167E7D6D8}C:\users\grzegorz\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\grzegorz\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{119D9628-A2C8-4188-960E-F98267C77023}C:\users\grzegorz\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\grzegorz\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{F326C710-2D30-4FB7-8DAB-05F11E2E829F}C:\program files (x86)\java\jre1.8.0_131\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_131\bin\javaw.exe
FirewallRules: [UDP Query User{92E31A5A-7CFB-44A3-BC4C-731F3695BB37}C:\program files (x86)\java\jre1.8.0_131\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_131\bin\javaw.exe
FirewallRules: [{19E060E3-1ECE-430D-BAC0-F8797D8F1790}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\USBSetup.exe
FirewallRules: [{378EFFA9-D38B-4A1B-A8A1-D20E317A0EC4}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{0007E9C5-CDC9-48EB-8D6C-77A5E370E3A0}D:\games\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) D:\games\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{CBD1C739-D003-4CE3-B323-2B8BCF0C59ED}D:\games\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) D:\games\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{64A7DC91-1D66-4C13-A71C-91270903BD35}] => (Allow) D:\Games\skyrim\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{FAAF8CBE-DC1C-414C-A649-89A130A3A9C5}] => (Allow) D:\Games\skyrim\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [TCP Query User{A665DC22-EED7-4EC3-8C6C-BDA06ABDB1F4}C:\users\grzegorz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\grzegorz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{3927888B-7516-4649-9040-0A6BE352E4AD}C:\users\grzegorz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\grzegorz\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{14F3F0F6-6EAB-4C7E-B0C8-EE4E59536240}D:\games\data\fallout 4\fallout4.exe] => (Allow) D:\games\data\fallout 4\fallout4.exe
FirewallRules: [UDP Query User{E6049955-2A70-4273-A1A4-F4DFEBAB8904}D:\games\data\fallout 4\fallout4.exe] => (Allow) D:\games\data\fallout 4\fallout4.exe
FirewallRules: [{CA0FCA18-802F-4094-AB25-C5E66152221F}] => (Allow) D:\Games\skyrim\steamapps\common\Arma 3\arma3launcher.exe
FirewallRules: [{B3BA7590-8418-4422-AA0A-BBC9E031895C}] => (Allow) D:\Games\skyrim\steamapps\common\Arma 3\arma3launcher.exe
FirewallRules: [TCP Query User{E5245197-73D3-4012-9CEB-FCD827999F78}D:\crossout\launcher.exe] => (Allow) D:\crossout\launcher.exe
FirewallRules: [UDP Query User{F2513F8B-6149-40EB-A842-8EBD145E57F6}D:\crossout\launcher.exe] => (Allow) D:\crossout\launcher.exe
FirewallRules: [{B9A1D06F-FD4D-4DC9-999A-DD2121ED791E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe
FirewallRules: [{E074D88C-78E1-48CE-AC8F-60B11E5734B5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe
FirewallRules: [{53CBCF34-2D1A-4F36-9BF5-4D3B297F8B02}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{ACD5131C-26E6-48B1-97A8-8326DD36508F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{DFA89ECE-56A5-4739-9E3C-EEB75865490B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{4B85AFED-11AB-41D3-81C8-65D188807376}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{12CD3301-6313-4CFD-8D8F-E481E5131804}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2DD471BE-8E72-41B9-A359-EB817D78A2AA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{5035CB27-1709-460D-8BA8-92B629603999}] => (Allow) D:\Origin Games\Battlefield 1\bf1Trial.exe
FirewallRules: [{1E13D255-37B2-44A7-85C6-2FAA49014BE9}] => (Allow) D:\Origin Games\Battlefield 1\bf1Trial.exe
FirewallRules: [{AFE6F83A-3BA0-43F2-B974-EEAE371C08B2}] => (Allow) D:\Origin Games\Battlefield 1\bf1.exe
FirewallRules: [{FEADFFCF-3C09-461E-889B-D24A4403EF4A}] => (Allow) D:\Origin Games\Battlefield 1\bf1.exe

==================== Punkty Przywracania systemu =========================

05-09-2017 11:33:49 Windows Update
05-09-2017 14:45:45 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
05-09-2017 14:46:13 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501

==================== Wadliwe urządzenia w Menedżerze urządzeń =============


==================== Błędy w Dzienniku zdarzeń: =========================

Dziennik Aplikacja:
==================
Error: (09/07/2017 05:39:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/07/2017 05:32:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/07/2017 05:20:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/07/2017 05:01:36 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Nie można wygenerować kontekstu aktywacji dla „c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu .
Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna.
Składniki powodujące konflikt:
Składnik 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.
Składnik 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.

Error: (09/07/2017 05:00:47 PM) (Source: MsiInstaller) (EventID: 1024) (User: ZARZĄDZANIE NT)
Description: Produkt: Adobe Acrobat Reader DC - Polish - nie można zainstalować aktualizacji 'Adobe Acrobat Reader DC
 (17.012.20098)'. Kod błędu 1603. Instalator Windows może tworzyć dzienniki, aby ułatwić rozwiązywanie problemów z instalowaniem pakietów oprogramowania. Użyj następującego łącza, aby uzyskać instrukcje dotyczące włączania obsługi rejestrowania: http://go.microsoft.com/fwlink/?LinkId=23127

Error: (09/07/2017 05:00:45 PM) (Source: MsiInstaller) (EventID: 11305) (User: ZARZĄDZANIE NT)
Description: Produkt: Adobe Acrobat Reader DC - Polish – Błąd 1305.Błąd odczytu z pliku C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA75401B744CAF070E41400\15.7.20033\PPKLite.api.  Zweryfikuj istnienie pliku i dostęp do niego.

Error: (09/07/2017 04:23:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/07/2017 04:15:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/07/2017 04:15:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nazwa aplikacji powodującej błąd: MSI_Trigger_Service.exe, wersja: [removed], sygnatura czasowa: 0x5243c86d
Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja: 6.1.7601.23864, sygnatura czasowa: 0x595fa536
Kod wyjątku: 0xe0434352
Przesunięcie błędu: 0x0000c54f
Identyfikator procesu powodującego błąd: 0x65c
Godzina uruchomienia aplikacji powodującej błąd: 0x01d327e367fbf443
Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
Ścieżka modułu powodującego błąd: C:\Windows\syswow64\KERNELBASE.dll
Identyfikator raportu: f2b3b4d3-93d6-11e7-a853-d8cb8abed7e3

Error: (09/07/2017 04:14:49 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikacja: MSI_Trigger_Service.exe
Wersja architektury: v4.0.30319
Opis: proces został przerwany z powodu nieobsłużonego wyjątku.
Informacje o wyjątku: System.Runtime.InteropServices.COMException
   w System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32, IntPtr)
   w System.Management.ManagementScope.InitializeGuts(System.Object)
   w System.Management.ManagementScope.Initialize()
   w System.Management.ManagementObjectSearcher.Initialize()
   w System.Management.ManagementObjectSearcher.Get()
   w MSI_Trigger_Service.Service1.DetectVGAInfo()
   w MSI_Trigger_Service.Service1.ServiceThread_Main()
   w System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   w System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   w System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   w System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   w System.Threading.ThreadHelper.ThreadStart()


Dziennik System:
=============
Error: (09/07/2017 05:44:01 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:56 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:51 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:46 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:42 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:37 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:33 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:28 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:24 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.

Error: (09/07/2017 05:43:19 PM) (Source: Disk) (EventID: 7) (User: )
Description: W urządzeniu \Device\Harddisk0\DR0 wystąpił zły blok.


==================== Statystyki pamięci ===========================

Procesor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
Procent pamięci w użyciu: 25%
Całkowita pamięć fizyczna: 8136.02 MB
Dostępna pamięć fizyczna: 6083.64 MB
Całkowita pamięć wirtualna: 16270.22 MB
Dostępna pamięć wirtualna: 14270.38 MB

==================== Dyski ================================

Drive c: () (Fixed) (Total:345.48 GB) (Free:24.53 GB) NTFS
Drive d: () (Fixed) (Total:585.94 GB) (Free:60.97 GB) NTFS
Drive e: () (Removable) (Total:14.55 GB) (Free:14.55 GB) FAT32

==================== MBR & Tablica partycji ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 554A4B9B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=345.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=585.9 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 14.6 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Koniec  Addition.txt ============================

 

Hi and welcome

Hope we can do this and work through differences in languages.

~~

Start Farbar Recovery Scan Tool (Please double-click on FRST/FRST64) with Administrator privileges

or Right click on the FRST icon and select Run as administrator
Highlight the below information then hit the Ctrl + C keys at the same time
or
Right click/highlight on the text below and select Copy.
beginning with Start:: and finishing with End::


Start::
CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Run: [aemskykoor] => explorer "hxxp://emargan.ru/?utm_source=uoua03&utm_content=dd5854e571ad34099da3550de30a623c&utm_term=60D4449A61B3A2E9E44C3C334500D7F0&utm_d=20170328" <==== UWAGA
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Run: [BingSvc] => C:\Users\Grzegorz\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
GroupPolicy: Ograniczenia <==== UWAGA
GroupPolicy\User: Ograniczenia <==== UWAGA
GroupPolicyScripts: Ograniczenia <==== UWAGA
GroupPolicyScripts\User: Ograniczenia <==== UWAGA
Toolbar: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000 -> Brak nazwy - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Brak pliku
Toolbar: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000 -> Brak nazwy - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers1: [AccExt] -> [CC]{2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => -> Brak pliku
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers1_S-1-5-21-3841648094-4281997214-1728550566-1000: [GGDriveMenu] -> [CC]{E68D0A55-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
AlternateDataStreams: C:\Users\Grzegorz:Heroes & Generals [38]
Emptytemp:
End::


Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

******

Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Here
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
    [external image: MBAM3_zpsw0f8rn9n.jpg]
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.

    If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
    Upon completion of the scan (or after the reboot), click the Reports tab.

    You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here

    ~~~~~~~~~~

    [external image: h3qKPnn.png]Malwarebytes AdwCleaner
  • Please download Malwarebytes AdwCleaner and save the file to your Desktop
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C0].txt) will open. Copy the contents of the log and paste in your next reply.
    – File, folder and registry backups are made for items removed using this programme. Should a legitimate file, folder or registry item be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[S0].txt.
~~~

please post
Fixlog.txt
Malwarebytes Anti-Malware log
AdwCleaner.txt

thanks for help

 

Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 20-08-2017
Uruchomiony przez Grzegorz (09-09-2017 09:36:36) Run:1
Uruchomiony z C:\Users\Grzegorz\Desktop
Załadowane profile: Grzegorz (Dostępne profile: Grzegorz)
Tryb startu: Normal
==============================================

fixlist - zawartość:
*****************

CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Run: [aemskykoor] => explorer "hxxp://emargan.ru/?utm_source=uoua03&utm_content=dd5854e571ad34099da3550de30a623c&utm_term=60D4449A61B3A2E9E44C3C334500D7F0&utm_d=20170328" <==== UWAGA
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\…\Run: [BingSvc] => C:\Users\Grzegorz\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
GroupPolicy: Ograniczenia <==== UWAGA
GroupPolicy\User: Ograniczenia <==== UWAGA
GroupPolicyScripts: Ograniczenia <==== UWAGA
GroupPolicyScripts\User: Ograniczenia <==== UWAGA
Toolbar: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000 -> Brak nazwy - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Brak pliku
Toolbar: HKU\S-1-5-21-3841648094-4281997214-1728550566-1000 -> Brak nazwy - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers1: [AccExt] -> [CC]{2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => -> Brak pliku
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Grzegorz\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
ContextMenuHandlers1_S-1-5-21-3841648094-4281997214-1728550566-1000: [GGDriveMenu] -> [CC]{E68D0A55-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
AlternateDataStreams: C:\Users\Grzegorz:Heroes & Generals [38]
Emptytemp:

*****************

Procesy zostały pomyślnie zamknięte.
Punkt przywracania został pomyślnie utworzony.
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => klucz nie znaleziono.
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\Software\Microsoft\Windows\CurrentVersion\Run\\aemskykoor => Wartość pomyślnie usunięto
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\Software\Microsoft\Windows\CurrentVersion\Run\\BingSvc => Wartość pomyślnie usunięto
C:\Windows\system32\GroupPolicy\Machine => pomyślnie przeniesiono
C:\Windows\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono
C:\Windows\system32\GroupPolicy\User => pomyślnie przeniesiono
"C:\Windows\system32\GroupPolicy\Machine" => nie znaleziono.
"C:\Windows\system32\GroupPolicy\User" => nie znaleziono.
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Wartość pomyślnie usunięto
HKLM\Software\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => klucz pomyślnie usunięto
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Wartość pomyślnie usunięto
HKLM\Software\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => klucz nie znaleziono.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Pending) => invalid subkey removed.
HKLM\Software\Classes\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => klucz pomyślnie usunięto
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Synced) => invalid subkey removed.
HKLM\Software\Classes\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => klucz pomyślnie usunięto
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Syncing) => invalid subkey removed.
HKLM\Software\Classes\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => klucz pomyślnie usunięto
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Pending) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => klucz pomyślnie usunięto
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Synced) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => klucz pomyślnie usunięto
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Syncing) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => klucz pomyślnie usunięto
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\AccExt => klucz pomyślnie usunięto
HKLM\Software\Classes\CLSID\[CC]{2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => klucz nie znaleziono.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\MEGA (Context menu) => klucz pomyślnie usunięto
HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17} => klucz pomyślnie usunięto
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\MEGA (Context menu) => klucz pomyślnie usunięto
HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17} => klucz nie znaleziono.
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MEGA (Context menu) => klucz pomyślnie usunięto
HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17} => klucz nie znaleziono.
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\Software\Classes\*\ShellEx\ContextMenuHandlers\GGDriveMenu => klucz pomyślnie usunięto
HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\SOFTWARE\Classes\CLSID\[CC]{E68D0A55-3C40-4712-B90D-DCFA93FF2534} => klucz nie znaleziono.
C:\Users\Grzegorz => ":Heroes & Generals" ADS pomyślnie usunięto.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 50850314 B
Java, Flash, Steam htmlcache => 401330133 B
Windows/system/drivers => 120163187 B
Edge => 0 B
Chrome => 23654142 B
Firefox => 391550409 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 15414490 B
systemprofile32 => 71770 B
LocalService => 66228 B
NetworkService => 1324 B
Grzegorz => 224047807 B

RecycleBin => 3842781 B
EmptyTemp: => 1.2 GB danych tymczasowych Usunięto.

================================


System wymagał restartu.

==== Koniec  Fixlog 09:37:24 ====

 

 

Malwarebytes
www.malwarebytes.com

-Szczegóły raportu-
Data skanowania: 09.09.2017
Czas skanowania: 09:58
Plik raportu: 9f79bb3c-9534-11e7-9982-d8cb8abed7e3.json
Administrator: Tak

-Informacje o oprogramowaniu-
Wersja: 3.2.2.2018
Wersja komponentów: 1.0.188
Aktualna wersja pakietu: 1.0.2760
Licencja: Wersja próbna

-Informacje o systemie-
System operacyjny: Windows 7 Service Pack 1
Procesor: x64
System plików: NTFS
Użytkownik: Grzegorz-potfur\Grzegorz

-Wyniki skanowania-
Typ skanowania: Pełne skanowanie
Wynik: Ukończono
Obiekty przeskanowane: 426919
Wykryte zagrożenia: 51
Zagrożenia poddane kwarantannie: 51
Czas, który upłynął: 13 min, 52 s

-Opcje skanowania-
Pamięć: Włączony
Autostart: Włączony
System plików: Włączony
Archiwa: Włączony
Rootkity: Włączony
Heurystyka: Włączony
PUP: Wykrywanie
PUM: Wykrywanie

-Szczegóły skanowania-
Proces: 0
(Nie wykryto zagrożeń)

Moduł: 0
(Nie wykryto zagrożeń)

Klucz rejestru: 4
PUP.Optional.MailRu, HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}, Dodano do kwarantanny, [663], [382913],1.0.2760
PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ccfifbojenkenpkmnbnndeadpfdiffof, Dodano do kwarantanny, [10], [405529],1.0.2760
PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\oelpkepjlgmehajehfeicfbjdiobdkfj, Dodano do kwarantanny, [10], [405527],1.0.2760
PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ojlcebdkbpjdpiligkdbbkdkfjmchbfd, Dodano do kwarantanny, [10], [405526],1.0.2760

Wartość rejestru: 3
PUP.Optional.MailRu, HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}|URL, Dodano do kwarantanny, [663], [382913],1.0.2760
PUP.Optional.MailRu, HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}|FAVICONURLFALLBACK, Dodano do kwarantanny, [663], [382913],1.0.2760
PUP.Optional.MailRu, HKU\S-1-5-21-3841648094-4281997214-1728550566-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}|SUGGESTIONSURL, Dodano do kwarantanny, [663], [382913],1.0.2760

Dane rejestru: 0
(Nie wykryto zagrożeń)

Strumień danych: 0
(Nie wykryto zagrożeń)

Folder: 16
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\_metadata, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\icons, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\js, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\USERS\GRZEGORZ\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\CCFIFBOJENKENPKMNBNNDEADPFDIFFOF, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\_metadata, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\fonts, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\img, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\USERS\GRZEGORZ\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\OJLCEBDKBPJDPILIGKDBBKDKFJMCHBFD, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj\7.1.30_0\_metadata, Dodano do kwarantanny, [10], [350800],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj\7.1.30_0, Dodano do kwarantanny, [10], [350800],1.0.2760
PUP.Optional.RussAd, C:\USERS\GRZEGORZ\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\OELPKEPJLGMEHAJEHFEICFBJDIOBDKFJ, Dodano do kwarantanny, [10], [350800],1.0.2760
PUP.Optional.Euphoria, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe\4.5.236_0\_metadata, Dodano do kwarantanny, [8129], [384781],1.0.2760
PUP.Optional.Euphoria, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe\4.5.236_0, Dodano do kwarantanny, [8129], [384781],1.0.2760
PUP.Optional.Euphoria, C:\USERS\GRZEGORZ\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\AHGGFMGIIDLACEICHJFEMGBAGGNBALOE, Dodano do kwarantanny, [8129], [384781],1.0.2760

Plik: 28
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\icons\128.png, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\icons\16.png, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\icons\48.png, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\js\browser-action.js, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\js\metrics.js, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\js\unity-stub-background.js, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\_metadata\computed_hashes.json, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\_metadata\verified_contents.json, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\manifest.json, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof\11.0.26_0\unity-stub-inject.js, Dodano do kwarantanny, [10], [350792],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\fonts\OpenSans-Bold.woff, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\fonts\OpenSans-Light.woff, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\img\128.png, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\img\16.png, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\img\48.png, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\img\512.png, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\img\search.png, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\_metadata\computed_hashes.json, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\_metadata\verified_contents.json, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\index.html, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\manifest.json, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd\12.0.12_0\styles.css, Dodano do kwarantanny, [10], [350798],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj\7.1.30_0\_metadata\computed_hashes.json, Dodano do kwarantanny, [10], [350800],1.0.2760
PUP.Optional.RussAd, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj\7.1.30_0\_metadata\verified_contents.json, Dodano do kwarantanny, [10], [350800],1.0.2760
PUP.Optional.Euphoria, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe\4.5.236_0\_metadata\computed_hashes.json, Dodano do kwarantanny, [8129], [384781],1.0.2760
PUP.Optional.Euphoria, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe\4.5.236_0\_metadata\verified_contents.json, Dodano do kwarantanny, [8129], [384781],1.0.2760
PUP.Optional.Euphoria, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe\4.5.236_0\background.js, Dodano do kwarantanny, [8129], [384781],1.0.2760
PUP.Optional.Euphoria, C:\Users\Grzegorz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe\4.5.236_0\manifest.json, Dodano do kwarantanny, [8129], [384781],1.0.2760

Sektor fizyczny: 0
(Nie wykryto zagrożeń)


(end)

 

 

 

# AdwCleaner 7.0.2.1 - Logfile created on Sat Sep 09 09:10:24 2017
# Updated on 2017/29/08 by Malwarebytes
# Running on Windows 7 Ultimate (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

Plugin deleted: MSN Homepage & Bing Search Engine -


*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [4939 B] - [2016/10/9 8:14:57]
C:/AdwCleaner/AdwCleaner[C1].txt - [3916 B] - [2017/9/6 19:29:40]
C:/AdwCleaner/AdwCleaner[S0].txt - [4536 B] - [2016/10/9 8:13:54]
C:/AdwCleaner/AdwCleaner[S1].txt - [1493 B] - [2016/11/24 17:59:15]
C:/AdwCleaner/AdwCleaner[S2].txt - [1566 B] - [2016/12/18 21:10:1]
C:/AdwCleaner/AdwCleaner[S3].txt - [4420 B] - [2017/9/6 19:27:45]
C:/AdwCleaner/AdwCleaner[S4].txt - [1533 B] - [2017/9/9 9:9:51]


########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt ##########

I can see quite a bit being picked up through Google Chrome.
I think it would be a good idea to reset Chrome.

[external image: U5NwUGc.png]Backup Chrome Bookmarks
Export bookmarks from Chrome
https://support.google.com/chrome/answer/96816?hl=en

[external image: U5NwUGc.png]Chrome: Chrome - Reset browser settings

~~~~~~~~~~~~~~~~~`

Zemana AntiMalware Free download it from here:


Double-click on the file named Zemana.AntiMalware.Portable to perform a system scan with Zemana AntiMalware Free.

You may be presented with a User Account Control dialog asking you if you want to run this program. If this happens, you should click Yes to allow Zemana AntiMalware to run.
When Zemana AntiMalware starts, click on the Scan button to perform a system scan.
without changing any options, press Scan

When Zemana has finished finished scanning it will show a screen that displays any malware that has been detected. To remove all the malicious files, click on the Next button.
Zemana AntiMalware will now start to remove all the malicious programs from your computer.
Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please restart your computer manually.
  • open Zemana AntiMalware again and locate the latest report
  • please paste the contents into your reply

  • When the process is complete, you can close Zemana AntiMalware
~~

Emsisoft Emergency Kit

Please download Emsisoft Emergency Kit and save it to your desktop. Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop. Leave all settings as they are and click the Extract button at the bottom. A folder named EEK will be created in the root of the drive (usually c:\).
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.
  • When update is complete, click Malware Scan. When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes. Emsisoft Emergency Kit will start scanning.
  • When the scan is completed click Quarantine selected objects. Note, this option is only available if malicious objects were detected during the scan.
  • When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.
**
Please post these 2 logs when finished.

Can you tell me what the computer is doing now?

Zemana AntiMalware 2.74.2.150 (wersja instalacyjna)

——————————————————-
Scan Result            : Zakończone
Scan Date              : 2017-9-9
Operating System       : Windows 7 64-bit
Processor              : 4X Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
BIOS Mode              : Legacy
CUID                   : 12B21FAA796F1D81F9145B
Scan Type              : Skanowanie systemu
Duration               : 19m 32s
Scanned Objects        : 112881
Detected Objects       : 4
Excluded Objects       : 0
Read Level             : SCSI
Auto Upload            : Włączone
Detect All Extensions  : Wyłączone
Scan Documents         : Wyłączone
Domain Info            : WORKGROUP,0,2

Detected Objects
——————————————————-

Chrome Search
Status             : Zeskanowano
Object             : Поиск@Mail.Ru - http://go.mail.ru
MD5                : -
Publisher          : -
Size               : -
Version            : -
Detection          : Podejrzane ustawienie przeglądarki
Cleaning Action    : Napraw
Related Objects    :
                Ustawienie przeglądarki - Chrome Search

Chrome Startup Url
Status             : Zeskanowano
Object             : http://mail.ru/cnt/10445?gp=811013
MD5                : -
Publisher          : -
Size               : -
Version            : -
Detection          : Podejrzane ustawienie przeglądarki
Cleaning Action    : Napraw
Related Objects    :
                Ustawienie przeglądarki - Chrome Startup Url

Chrome Homepage
Status             : Zeskanowano
Object             : http://mail.ru/cnt/10445?gp=811013
MD5                : -
Publisher          : -
Size               : -
Version            : -
Detection          : Podejrzane ustawienie przeglądarki
Cleaning Action    : Napraw
Related Objects    :
                Ustawienie przeglądarki - Chrome Homepage

[removed]
Status             : Zeskanowano
Object             : %appdata%\mozilla\firefox\profiles\73h4lfqh.default\extensions\[removed]
MD5                : B783F45D3E264115E541989FE1BECDE4
Publisher          : -
Size               : 706895
Version            : -
Detection          : PUA.FirefoxExt!Gr
Cleaning Action    : Napraw
Related Objects    :
                Rozszerzenie przeglądarki - [removed]
                Plik - %appdata%\mozilla\firefox\profiles\73h4lfqh.default\extensions\[removed]


Cleaning Result
——————————————————-
Cleaned               : 4
Reported as safe      : 0
Failed                : 0
 

 

Emsisoft Emergency Kit -Wersja 2017.8
Ostatnia aktualizacja: 2017-09-09 13:56:56
Nazwa użytkownika: Grzegorz-potfur\Grzegorz
Computer name: GRZEGORZ-POTFUR
OS version: Windows 7x64 Service Pack 1

Ustawienia skanera:

Typ skanu: Malware skan
Obiekty: Rootkity, Pamięć, Ślady, Pliki

Wykrywanie PNP: Włączone
Skanowanie plików skompresowanych: Wyłączone
Skanuj archiwa poczty: Wyłączone
Skanowanie ADS: Włączone
Filtr rozszerzeń plików: Wyłączone
Bezpośredni dostęp do dysku: Wyłączone

Skanowanie uruchomiono:    2017-09-09 13:58:26

Przeskanowano:    57809
Wykryto:    0

Koniec skanu:    2017-09-09 18:06:39
Skan trwał:    4:08:13
 

DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
************************************
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: jv4nhMJ.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png]Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: j1OLIec.png]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: sHjS79L.png]Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
Want to help others? Join the ClassRoom and learn how.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI